Skip to main content

Ransomware, extortion and the cyber crime ecosystem

A white paper from the NCSC and the National Crime Agency (NCA).







Despite the variety of criminal services available, there is a high level attack path for ransomware that can be broken into functions delivered by different malicious actors (Figure 2). The chronological flow of an attack is typically left to right, starting with an initial interaction with the victim on the left, and increasing in impact moving towards the right.  In many cases, organisations are not aware that they have become a victim until the very end of this process.

Figure 2. Simplified Ransomware workflow

It’s worth noting that:

  • each function can be conducted by a different threat actor and sold to each other as a service
  • malicious actors can execute more than one function themselves as fits their working methods, skills and capabilities
  • some of these functions are also optional, such as TDS (Traffic Distribution Systems), which is used in some malware delivery, but not others.

This attack path is supported by a wide range of services, including criminal forums for discussing and exchanging services, anonymisation tools and malicious ‘bulletproof’ hosting that claim to provide infrastructure services that are resilient to takedown from law enforcement. Each of these underpinning services are necessary for the ecosystem to function but are outside the scope of this document.


Direct exploitation

A common method for gathering initial accesses is to scan the internet for devices with known vulnerabilities. Some groups use commercial datasets for this such as Shodan, but many others conduct the scanning themselves, as it is not a difficult process to set up. Criminals look for devices that are likely to be in businesses (rather than home environments). Examples include Microsoft Exchange servers, platforms such as Citrix or VMware, VPN devices and firewall devices.

Figure 4 covers global volumes of Microsoft Exchange servers that are vulnerable and where the patches have been available from Microsoft since 15th February 2023. The graph shows minimal change in overall availability of exploitable devices over the months after the patch became available. This trend indicates that despite patches being available, they are not being consistently applied, and there are still rich pickings for cyber criminals to use as an initial access. From June, the volume of unpatched devices is estimated to approximately 10% of the total available servers, which sounds good, but 10% accounts for around 700 unpatched devices predominantly in businesses which is still a large opportunity for criminals.

Figure 4. Shadowserver tracking of Microsoft Exchange exposure (Dashboard · The Shadowserver Foundation)
 

Criminal use of exploits often surges shortly after certain critical patches are released indicating they are being reverse engineered from the patches. In most cases, an exploit is widely available in the criminal forums in less than one week from the patch being released.

A zero-day exploit is a recently discovered vulnerability, not yet known to vendors or antivirus companies, that criminals can exploit. Cyber criminals don’t need to develop their own zero-day exploits as doing so is expensive, and there are many devices ‘in the wild’ that are not patched regularly. However, some actors have been known to use zero-day exploits, most notably there are public reports of Cl0p’s use of the Accellion, GoAnywhere and MOVEit vulnerabilities. This would account for the large spike in Cl0p victims in Figure 1 in 2023. Actors conducting ransomware will buy exploit code from other criminals, or modify exploit code from GitHub.

Note: The NCSC strongly recommends creating a vulnerability management plan that prioritises vulnerabilities that are accessible from the internet. The list of exploits being used changes rapidly based on the availability of vulnerable systems and the introduction of new exploits to the market, so it is not enough to just patch those known to be currently in use.

Brute force access
 

As previously discussed, poor password practice is another common access vector for enabling ransomware. In the same way actors can scan for known vulnerable devices, it is equally straightforward to scan for a device type and test common passwords in brute force attacks. In some cases, default passwords (that are widely known and shared) have not been changed. Tools like Crowbar, Hydra and NLBrute, specifically designed for conducting brute force attacks, make it easy for malicious actors (who can also use the same approach with certain network perimeter devices and common services such as RDP or SSH) to gain access.

Malicious actors will also use passwords from previous database breaches to gain access to current systems, since password re-use is relatively common. There is a premium charged for fresh accesses from recent database breaches, since most breach databases are often older (and therefore less likely to work in ransomware attacks).

Stealers and loaders

‘Stealers’ are a type of malware available on criminal forums that are used to harvest a variety of useful information (including credentials) which other criminals can use in fraud and/or ransomware attacks. In some cases, versions of the stealers have been leaked onto GitHub making them widely available for anyone to use. Prices range from hundreds to thousands of US dollars per month.

Figure 5. Screenshot of Raccoon Stealer advertisement translated into English
Figure 5. Screenshot of Raccoon Stealer advertisement translated into English

Common features of stealers are:

  • stealing passwords stored in web browsers
  • stealing cookies, browser version and other configuration details
  • stealing form entry data from web browsers
  • stealing stored credit card details
  • taking screenshots
  • capturing antivirus details
  • logging keyboard presses from users

This malware can evade detection by antivirus software due to the availability of criminal services that specialise in ‘crypting’ or modifying malware to ensure it’s not detected.

Note: Although the credential stealing malware described above is used to access passwords stored in web browsers, the NCSC’s advice for general members of the public remains to store credentials in web browsers. This prevents the majority of users from using easily-guessed passwords (or re-using the same passwords across multiple accounts), both of which put people at risk following large scale data leaks when online services are compromised.

‘Loaders' are another type of malware used to gather basic system information which is then used to deploy other malware. Loaders can be used to determine if a system is viable for ransomware before deploying more capable malware (and spending the time necessary to take over the whole network).

We’ll often see a blurring of functionality, with some loaders gaining stealer functionality, and some stealers operating as loaders. Loaders were more common at the start of the growth in ransomware, with loaders such as Emotet and Trickbot leading to large volumes of victims that actors could choose from. More recently they are less common, with stolen credentials and vulnerable devices being a more readily available access.

According to reporting in PWCs Strategic Intelligence Bulletin* see footnote, the most popular stealers on the market are RedLine Stealer, Raccoon Stealer and Vidar. Many criminals use these tools to steal credentials. Cyber crime marketplaces make it very easy for criminals to sell these stolen credentials in bulk. These marketplaces are similar to automated vending carts (AVCs) discussed in the previous NCSC cyber crime report, and allow criminals to buy credentials, typically under $100 for most services.

Genesis is one such marketplace that was subject to a law enforcement disruption and prior to the disruption was among the top 3 reported credential marketplaces. Genesis also provided browser cookies and fingerprints so actors can mimic the original device and bypass authentication checks. These stolen credentials are preferred to large breach databases, as they are more recent and used by fewer criminals, and so more likely to work. Stealers are increasingly used outside the corporate environment due to the increase in home working and bring your own device (BYOD) initiatives. The availability of credentials for sale has been increasing as illustrated in the diagram below:

Figure 6. Approximate credential availability on Russian Market criminal forum 2022 vs 2023. Source: SecureWorks
Figure 6. Approximate credential availability on Russian Market criminal forum 2022 vs 2023. Source: SecureWorks

The deployment of MFA on remotely accessible business accounts makes using stolen credentials much harder for criminals, but there are - at a cost - services that use social engineering techniques to bypass these mitigations. 

Distribution

Loaders and stealers require distribution to gain large victim volumes. Phishing services on criminal forums supply this distribution by sending a large number of emails with malicious attachments, or links to trick users into visiting malicious websites. Other popular distribution techniques include:

  • malvertising (when an attacker uses advertising as a delivery method for malicious activity)
  • SEO (search engine optimisation) poisoning to return malicious links to common search terms
  • embedding malware in cracked software

Traffic Distribution Systems (TDS) also play an important role in malware delivery. A TDS is similar to legitimate advertising services; they receive visits from users who have clicked links in malicious emails, and capture basic system information such as geographical location, browser or operating system version. The main benefit of a TDS is that it allows cyber criminals to define redirection rules from an administration panel based on the type of visitors browsing the system’s web of malicious landing pages. This means that different categories of visitors can be redirected to different campaigns, depending on the target audience.

TDSs were very popular with exploit kits to ensure the correct exploits were used against the right browser to minimise the risk of detection. More recently they are proving very popular in phishing distribution, blocking known security research IPs from receiving the malicious payload for analysis.

* CTO-SIB-20230224-01A - Strategic Intelligence Bulletin: We can steal it for you wholesale”, Price Waterhouse Coopers, 2023



In-house

The traditional ransomware business model is a full ‘in-house’ solution, where the same threat group responsible for developing the ransomware conduct much of the attack. That is not to say they do not require the marketplace, in fact many still use it for parts of the attack chain, including for cryptocurrency services.

The group behind Conti ransomware predominantly followed this model. While they recruited operators (affiliates), the payment model was very different to ransomware as a service. Since the group provided most of the accesses, the tooling and operating procedures (as well as the ransomware itself), the group held onto the majority of the profits. Most of the operators are understood to have been salaried and took a commission from the ransomware payments with the rest going to the core group. This is largely reflective of car sales models in legitimate businesses, where the salesperson receives a base salary (and annual leave, and suchlike) but is encouraged to make more sales through the use of commission.

While this model is less common, some groups still primarily operate as an in-house business model. Ransomware such as Cuba and Vice Society are not available for sale in the criminal marketplaces. In the case of Cuba ransomware, access was primarily via the Hancitor Loader. Vice Society typically do not use loaders, and are routinely observed conducting attacks against the education sector. Use of a common access vector or targeting profile suggests it is a single group conducting these operations from the point of access to the deployment of ransomware. Access vectors and other behaviours are much more diverse in ‘ransomware as a service’ models.

Ransomware as a Service

The ransomware business model seen most frequently is ‘ransomware as a service’ (RaaS). In this model, ransomware groups typically provide a web portal to enable affiliates/customers to customise their ransomware and obtain new builds with unique encryption keys per customer. Many include a communications platform to make the ransom negotiation easier and more anonymous for the affiliate. Most ransomware will also include features to delete local backups to hinder recovery. Other features of the service include access to data leak sites, where affiliates can publish stolen data as an added incentive for victims to pay.

RaaS groups are often aware of western laws and regulations and use that knowledge to shape their criminal activity. Data leak sites became popular in the hope of pressuring victims that could face large fines under laws such as UK GDPR and the Data Protection Act 2018. While the threat of leaking sensitive data (whether intellectual property or personal data) often carries real weight with victims, the victim can be liable for not protecting the data, regardless of whether it becomes public on the leak site.

A recent example of this can be found in the reported negotiations between Lockbit and the Royal Mail, where the malicious actor attempts to use this leverage, failing to grasp that the very public nature of the attack (and that LockBit publicly claimed the attack) means that paying to prevent the data release does not necessarily prevent the victim being fined for the breach. They could have paid an exorbitant cost to the criminals, and still be subject to GDPR regulations and potentially be fined. The relationship between RaaS group and affiliate can further be observed in the reporting around this incident, as LockBit initially denied responsibility until the group identified which affiliate conducted the attack.

There are many subtle differences between the RaaS groups as each attempts to refine their business models for maximum profit. Some will deploy ransomware attacks on businesses dependent on IT systems (such as manufacturing and logistics) but conduct data leak-only attacks (with no encryption) against sectors where the data privacy is more important, such as law firms or healthcare services.

The most important thing to note about RaaS is that typically it’s the affiliate that obtains and uses the access, not the RaaS group. This is an important distinction in the eyes of the law and is actually two different offences under the Computer Misuse Act (CMA) (1990). Writing and selling ransomware falls under Section 3A of the CMA, while the affiliate conducting the attack is subject to Section 3 or 3ZA (depending on the impact).

One example of this is the attack on Royal Mail, which was publicly attributed to LockBit. However, LockBit are simply the RaaS group who are said to have provided the ransomware, it would have been a LockBit affiliate that obtained and exploited the access. While many RaaS groups have ‘terms of service’ that prevent affiliates ransoming certain targets (such as healthcare and critical national infrastructure) the enforcement of it is varied between groups. In some cases they ‘vet’ the victim before supplying the ransomware. In others it is retrospectively applied, and may mean they won’t supply to the affiliate for use in future attacks. In either scenario, the control the RaaS group exerts over the affiliate is often after the point of compromise.

The enforcement of the terms of service reflect a risk-driven approach to the attention RaaS groups invite from UK and international law enforcement. Law enforcement activity can reduce the popularity of a criminal service, with affiliates switching to other brands. This was seen with the DarkSide ransomware that the FBI has said was used in the attack on the US Colonial Pipeline, resulting in widespread disruption to the US east coast. The Darkside ransomware collapsed as a brand after law enforcement seized the cryptocurrency of the affiliate that conducted the attack.

In recognition of the increased skillset of the affiliate (and the fact they do a larger portion of the work), the RaaS group typically takes a smaller percentage of the ransom. Until recently this was approximately 45%, but with the increased competition from more RaaS groups, that figure has decreased.

Post exploitation tools

Post exploitation tools are primarily used by affiliates. They are often tools that are built for system administrators or legitimate adversary simulation teams to enable improvement of system security. They are a challenge for security professionals as they are legitimate tools and are widely available, so they can’t simply be banned/disrupted wholesale in the same way that malware can.

The most popular of these tools is Cobalt Strike. Other tools include Meterpreter, Sliver and Brute Ratel. To evade detection, criminals are also using existing administration tools and free trials of legitimate remote management software, such as Atera and Splashtop. Many criminals are not experts in conducting attacks, and groups will also sell accesses to those actors who don’t have the skills to use the tools effectively.





Published

Version

1.0